Time flies when you're having fun. Measure spiders when you're not.
At the end of August 2024, NIST issued some new guidance documentation (SP-800). Of specific interest is their recommendations around passwords (in SP-800-63B) – because it conflicts with what many organisations actually do, and addresses a few bugbears of mine. Even with widespread adoption of Multi-Factor Authentication (MFA), passwords are not dead & buried yet.
“To set, or not to set: that is the question:Whether ’tis nobler in the mind to sufferThe slings and arrows of outrageous password rules,Or to take arms against a sea of hackers,And by opposing, end them? To change, to forget—No more; and by a forget to say we endThe heartache, and the thousand natural shocksThe